Description
Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.
Published: 2026-04-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Update
AI Analysis

Impact

Missing authorization in the Eniture technology LTL Freight Quotes – Worldwide Express Edition plugin allows an attacker to gain access to functions that should be restricted to authorized users, as identified by a CWE-862 Authorization Failure concern. The vulnerability could enable manipulation or exposure of shipping data, potentially compromising confidentiality and integrity of business processes. The CVE description confirms that incorrectly configured access control levels create this exposure.

Affected Systems

The issue affects the Eniture technology WordPress plugin LTL Freight Quotes – Worldwide Express Edition from any version up through 5.2.1. Users running version 5.2.1 or earlier must check their installation for the presence of these versions and plan for an upgrade.

Risk and Exploitability

The quantified CVSS score of 5.3 indicates a moderate risk level. Exploit probability data are not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploits. Attackers would likely target the plugin’s web interface or API endpoints, implying a remote attack vector. In the absence of further technical details in the CVE entry, it is reasonable to infer that the plugin exposed endpoints that do not enforce proper authentication or authorization checks.

Generated by OpenCVE AI on April 7, 2026 at 09:20 UTC.

Remediation

Vendor Solution

Update the WordPress LTL Freight Quotes – Worldwide Express Edition Plugin to the latest available version (at least 5.2.2).


OpenCVE Recommended Actions

  • Update the LTL Freight Quotes – Worldwide Express Edition plugin to version 5.2.2 or later

Generated by OpenCVE AI on April 7, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Eniture Technology
Eniture Technology ltl Freight Quotes – Worldwide Express Edition
Wordpress
Wordpress wordpress
Vendors & Products Eniture Technology
Eniture Technology ltl Freight Quotes – Worldwide Express Edition
Wordpress
Wordpress wordpress

Tue, 07 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.
Title WordPress LTL Freight Quotes – Worldwide Express Edition plugin <= 5.2.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Eniture Technology Ltl Freight Quotes – Worldwide Express Edition
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-07T13:11:05.535Z

Reserved: 2026-03-31T09:57:35.161Z

Link: CVE-2026-34899

cve-icon Vulnrichment

Updated: 2026-04-07T13:10:30.449Z

cve-icon NVD

Status : Deferred

Published: 2026-04-07T09:16:21.340

Modified: 2026-04-24T18:08:35.440

Link: CVE-2026-34899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:49:51Z

Weaknesses